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(54) SYSTEM AND METHOD FOR CONVERTING KEY 

(57)Abstract: 

PROBLEM TO BE SOLVED: To provide a key conversion system 
for deterministically and reversibly converting the first key value of a 
first communication system into the second key value of a second 
communication system 

SOLUTION: The key conversion system generates a first 
intermediate value from at least a portion of the first key value by 
using a first random junction. At least a portion of the first 
intermediate value is provided to a second random junction for 
producing a second value. Exclusive- OR(XOR) is preformed on at 
least a portion of the first key value and at least a portion of the 
second value and a second intermediate value is generated. At least 
a portion of the second intermediate value is provided to a third 
random function for producing a third value. By performing 
excLisive-OR on at least a portion of the third value and at least a 
portion of the first intermediate value, the key conversion system 
produces at least the first portion of the second key value, and at 
least the second portion of the second key value is produced as the 
second intermediate value. 
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(S ME KEY) #SftJ|Sft, MBS^CCTDMA^^ 

KEYlt U I MfeJ:^VLRtcJ:orP?(Z)^iteB#(c^ 

tCP-5 >^S»£-fC»\ SMEKEYB, VLRCC 

**TT££*, SMEKEYB, UlMfeJ;OT-« 

net vlr cd jrfRr cc iotfiisns. 

[ 0 0 1 7 ] 2 G C DMA^SJf«B«H©*ffiK J:S« 
^IB^rfflt^^, 5 2 Ofcfy hVPM©fttoOec, 
^-Fa>^-f7X^ (PLCM) ^CD^rS4 
It, V P MO 4 2 STli y h (LSB) ^Ut^ 
^ 0 COPLCMB, J^OflH8©fc»OflJDBft^ 
^7>^WX^iUtfflC^ti5 0 4 2 tT^/hPLC 

LC^-b'Xffi^>X7"A^SIfi$n^ 0 SMEKEY 



9 

tt. TDMA3%©^£l§ID<£5{cm>?>ft£. 
[0 0 18] IS-4 1 3G-fe^ 3 ^^IJUM 
TS-te^ ^ Uf ^S^tfei], -efty:. UIMK 
J: o T|B] D^ft* 3 ft § mc . 12 8t7h Bf#^t« 
CKfci^ 1 2 8 tf * I-Sg£ttftBfli IK^, USB 3 ft 
fc ^ X t- A © V L R ^ jl $ ft 5 C £ t ca~? < = 

[0019] te^jr.^ . y h *saf^fA^r*o-? > 

cjer a- =f y x a o . «: j: ~> x m/ma&s k 

S43ti5)S^r*^tt, 3 Gis^a 10 
[0 0 2 0] 

[ISSIJjWB&L/J: 5 £•$-■£»«] *l§HJ3©SWi*, HI 
©iSffi^7-A©!j| 1 ©SifiI#>6H2 ©jiff i/XrA© 

[0 0 2 1] 

xfAB, Hi ©^^'AUBi^ffl^T, Hi©#ifii© 

'pt£< tt— aj*»6Sfi©tt>innB**jaws. hi©* 

BHfi©*l>Sc < £ *»— SPtts H2 ©tt*£j*-rafc«>fcftl 
2©v>^AHB^ic^x.6ft5o H 1 ©SHB©4>& < £ 
t-gP£> H2©fil©^&< ife-WiKfe^TSMfiW 
ffcfflffl (XOR) ^»fSft. H2©^fi^iSSft 
S. H2©TOffl©^< i*>— Wt*. S3©f4M 
T-Sfc&CcH3©7>#A|IBifc&C^;te>ft&„ ®3 0i 30 
©4>fc < £ t>— »& . H 1 ©tp^ffl©^ < £ fe-SP£ 
(cfctiTj»flM<flWPn**fT T ■£> C £ Set 0 , ggQft^ 
X-r-ABH2©«ffi©^< £ &H1 ©9i^££Jj£U 
H2 ©Hf8©4>& < £ tH2 ©as#ttH2 ©t£HBffi£ C 

r£fiS3ftS. ?©M->xfAit Hi©$tfi£-^ 

A-5£*, JfcsKUz- » hfc^omiailftv'XT-A^, ft 
«*33JW-Se£*ieW£-rSC£&<. |b]DH2©« 

ffl*^-r-sc£icjfea£L^*-c^iie { jr*€)„ 

[0 0 2 2] fO«^>^fA(l «9R3.-9 h^H 

1 ©fflff s^-?-ak:^> Lril-il^tcH, H2 40 

©aff'>XT-A©H2©»ffl^, h i ©aft ^x^A© 

Hl©gtffi&C^&LTK3ftS£05*rBJjm AS 
t»5i)S05ffilWr*S. »>^?A8, H 

2©HfiI©4>&< t&l2 0S»*S3©5>^MS[ 
(C^*., H3©fit££fSnr§ 0 H2©gtfil©^&< £ t 
Hi©3^£, H3©ffi£Kfct>T, gfffiWt&affl^H 
trr£C£K:J:9, HlOtflfi^JtiS. H2© 
5>yAB8it*ffll4T. I^->X?AB, Hi©™ 

m^hm2(Dm^mh. H2©ffi£. H2©^fa©H 

2 ©BB#£ iCfe^TPffeWiiaflJ%j|ff-r £ C £ K J: 50 
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*], ii ©§tffi©d>& < £ *>— a5**fi£-r a. §t^r> 
xfA«, H2©iifit©(2^££T£5ft;^oT^£i# 

*ati«DT, Bft#$ft/c-fe^ or 4 ihj« 
k, mi ©afB©^^£^£^r^ft^^r^^f©^••c^fe 
->ti H2©Stflitt^SicBi$ft^i^ 
[0 0 2 3] *|ffla©fl&©«fil*J«tDfjFa^itt, £{TfciB 

*g s ft €> imbrc bhb &te» , in m*&mr ntfW6*K 

[0 0 24] 

-efttt. H 1 ©aft^>^T-A£H2©iiff i/XfAi© 
fltD-^^Sila-^ h ftfcSi 
^€:S«TS„ i^^fAB, Hl©afl^T- 
A©mfcf? h©iHiI£, H2©ilffVX7-A©n tf^ h 

ITB €Ol»>^fAB, 3 0©7>^'AH8iit 

»gB, mt'^F A* 9 s - *5>J* . 5 > y Af^KSSfK L 

Mi^h«, n-niK-;ff-m ^ > ^AifcicSfK 

fj, 7>^Aicm^.S J:5(C, AMtUAKV'yfyi/' 

^(c*st>r, ^>^'am^;«|S5;dt 5 A-S„ fc£AES, 5 
Zs&l>MW&, WfAffl^> F^-^tcMfti-teliaff 

i'XfAi, iia-^ h £ic .fc-o-cfti^ftri^o 

[0 0 2 5] -€-©«^>XT-Ati, mfy KStfB*^ 
A S £ * . y h fe i i^to^aff t- a^ ft 

WDsafcSiias £ -r c £ a < , in d n e h .afa^^ 

t-a«, MMzL-'y h*s^> h't^Ltf l©Iii/^ 
T-AtcM-S^ictJ, H2©Mff ^fA©n t" hit 
^j^3ft, Hl©aff>'X7 : -A©mt;-> h»cKS£ 

7-Att, nt'i- ^©afii©ia£^£^r^ft^^r^^ 
y h©«fa^sic»s^-r§c 

■So ibjuhc, mfc*-^ ^©«^ii©^i£^£"^r^fc^-,r 

ftfti^ 

[0 0 2 6] ^©H^SsiCJtSDT^ s» h*^ 

* c ^ jif t >- x f- a £ if u i > a ft ^ X t~ A £ © © J; 5 

tC, 2o©4a^aff ^^T-APaTrn- iyi'tSK, 
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CC, 05OIS-41 SGWa'Jf^B, VL 
R8 OteiC^lll^y F 1 2 0 (ftiWJl 2 2) K 
fel^T, 5 2 0 by F VPM4VLR 1 1 OsEo^SfiS 
nfc64t ^SMEKEYil^Wt, 128 b 

v hCKtectcjf/aEfc i 2 8 by f i Kec^ft-rSc a? 

A*6 2 GTDMA^Xf >^*rSR»C, I 

S-41 3Gi2+ a yf ^Stt, VLR80fc±ff 10 
ffl&zL~y F 9 0 (&SW29 2 ) 5C*rt,>T, 12 8b* 

* hCKte«£tf/S;fctil 2 8 by F I K*. 64t^; 
hSMEKEYifift^btifcS 2 0 by F VPM&C^ 
UTTS,, VLR80B, VPMtoAiJSMEKEYSV 
LR 1 1 OfCjiiRTSo 

[0 0 2 7] M7t<C^£tiZ>J: F^2 
G CDMA^fA*6 3 G^y^ACCtf-S 
SISK, IS-41 3GW^'Jr^S», VLR 
8 0W«^^120 (ftSl^ttl 2 2) 6Ct5 
t>T, 4 2 by FPLCM^VLR 1 1 0^6§fi J*to 20 
fc6 4by F SMEKEYijBft^bft, 1 2 8 by 
hCKfciE>yifc 1 2 8 b y F I KtC^ft-rSo 

A#>i&2 G C DMA^fAJCP- 5>^fSIS6C, 
IS-41 3G-fe+^'Jr^^ VLR80fei 
0 (*£t*B:9 2) &C*5l>T, 128 
t y FCKfciff/S ftili 1 2 8 H Kt, 64b 

* F SMEKEYiI*^bttfc4 2 by F PL CMtC 
SSftT So VLR80ft P L CMfci^SME KEY 
^VLR 1 1 OtcMftT^o 30 

[0 0 2 8 ] H9&C^3ft£J; ftag^L--, F#2 

G GSMVXfA^63G UMTS^fAiCO- 

UMTS 3G-fe^^yf ^SJt 
VLR 8 O^i:^!!^^ h 6 0 (ftSlifie 2) 6C 
te^T, VLR 5 0*>6S« 3*ifc6 4 b y FK C 

1 2 8 by hCKtect^/Sfc 1 2 8 by F I KtC^gfe 
TZ> a i»CC, H 1 0 &C^£ft5 <fc 5 il^^F^ 
3G UMTS^rA^?,2G GSM^^Afcn 
-^yTSBKC, UMTS 3Gi2 + ^Vf^S 
tt, VLR8 0fcJ;^W^^9 0 (*Sl*tt9 40 
2) &C*5^T, 1 2 8 by FCKteJ:tf/*fcB 1 2 8 
tyUKt 6 4 by FK C KSBftTS. VLR 8 0 
K c 4VLR5 O&CjiffiT&o 

[0 0 2 9 ] L/fc^oT, *Sg||ft7£JliT'«, ff LA> 3 
Giifi->^^A(Z)J:^%, SI 1 ©afs^^Atctol* 
r, «*3hft:JnA#ISiE (ESA) *s<tcxefc#3hfti 

snA#^^-f^^- (esp) tcwjer-sftai^-^ f 

B, &WL<D7'U^t/-t- F*HSU *t^2G T 

HSiajiy h^4^r;WyXA4ffl^l>77>f 50 



BB2002-232418 

12 

FB, E S PJC^lELftt^l^2 0ffiM>'X^A<Dit 

aft ^x^a-x6[)^> F^v^iCtsi^nsi^, si^ 

*l^2©ffifB^X^A3W^jSrSM^^^^^ 

- r ;b y Xa©/c s> fcijjB ttfttt fc£BW £ 

di*Sr#S a ®2coaff ^X^AOfcfcCDUtt, SI 1 

^Atastae»wr*sft:ft, ii^^ Ft, #imij© 

SSWfT&CiKiJ:^ #2©«ft^;*^A©fc»©« 

[0 0 3 0 3 -C-OSISCft^^Att, iKD^XrA^ 
6CD«£l^2©S^^A^6©St&C^y b>^U $6 
tcS^TC^MTc 3 Gaff WrAi 2 G 

TDMA^f AitD^r^Xf A0a> Ftf^SJIfT 
-rSISCC, *CD*^ft^^Att, Ut-^«CK^r, VP 
MASK/SMEKEY (VS) Wcv^ty^t^C 

tt^W"T^ 0 1) 1 2 8 by FCKB5 8 4 by FVS 

tcvyb>^§ns 0 2 ) pJMWr & o , 5 

8 3 by FVS#S1 2 8by F C KKjKtC V y b> ^3 
3 ) *<D«fBtt, 5 8 4 by Fit©— r> 
T*>. «A#38*CK*B*r*a^J:5K:as*, 12 
8 by FUCKO— BI5J»btfPoTfc, ftA#^5 8 4 b 
y FVSS:S*t?*a^J:5 5caSMi»r$^rftS 0 
ftiWrB, /ciitl y F©^2CDafl> / -X7 u 

A<t o A*«c«li*W'rs» i oaft^x^Acctei^r 

ACDgiffi*, ^2 0aff^-X^ACD^fiitCVy b>^"T 

£ D L,*0tt**&* iS^^h^IioiivxrA 
SSI <DmSi/X^l±<Dtc&<DigM<DMm£^ y b> 

[0 0 3 1 ]fcii« t 2G TDMA^fAt^lf 
TS*^, 3G^^7 : -A-.(Z)->X^Ar0l^> F*^*H 
tTTSKJC, i$»->XfAB t VPMASK/SME 
KEY (VS) *f*Bf-^SICKt£:vy f>^T4Ci*t 

r»4 0 cc^aB5i»rtt, agesHSffia. 5 8 4by 

FVS^rl 2 8 by FCKCCVy f>^tS fl 
y F3WS2 G TDMA^rAiC^y F^^ bt!5J| 
^CCtt, iffl^fAil 12 8byFCK*584 
by hVSK^yt^^L/tSW ffUOS 8 4 by 
FVStt, ftfiJCDS 8 4by FVS*|p|DrB3&l^i»^ 
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3G^fA^6 2G TDMA^^fA^O 
gi©A> Ftf ?B*ftA>5 8 4 tr^ hVS2HSfTr& 

B, 1 2 8 t v hCKBWteHLHSecflg$3ftS. 
[0 0 3 2 ] C6D3H*?K«rB, l»>^fAii, 9f 

Is—TJbziV XAQ/c&GC/B^6ft&SI(DJ: 02 10 

b, *©£8MM8B, ifL^»i(Z)iim^^^Ai;c*5^ 

S128tT^hCK*. *t^2<DMfi^^^A©fcft 
CDV PMASK/SMEKEY ( V S ) gl$C^g|T& C 
£fC&& 0 VPMASKBS*lSl©»^CC2 6 0 fcf* h 
7X^6^0, SMEKEYB, S^ilff ^fAK 
J:otffll^n^5 8 4 tT^ KD»^CC6 4 fcf * hS 

l*Mfl^^f-ACCOliT©tWR*J#fc"f, 5 8 4 fcT* h 

±x^mLimm^^^^cfm^-^v^>^6 Q 58 4 

fcT* Hioafil©K, IrLiaf^fAB, 1 2 8 e 
^ hCK*B4t5^*5Ci*»BL, ^fti$ 

5 8 4 hf* m^scKSS-f-riri^^,, 

[0 0 3 3] mm^~y hte£&MSCfcte\i*Xf$lg t £ 

n*vs«BraDKa*^»r*s. cftB. vsitco 

I > T £D 6 ft x t i S ffi MOfl&Ofi i CC <D ^1^^ & W ft B 

l« (fciitB, ^>#A»> # % sanwcc, 
ci©iHirfiWR*S»-r*c:i*iMi£'er, ck^v 

[0 0 3 4] §6tc, *^Mfi ^X-rArtOil^jcio 
WL^afi^^A3W|iaift«»*CiBttl4J:5 
CftB, — *|SlKHi#ffcJ8?«*Ml^ 

OlSS, COW^BVSSS<D<fc5a*l^fflft^?A<D 

rBCK||OJ:5tt9rL/lia<i^^^A©||«:W*r* 

^RliKWCCTSCiKttD, ±i2<Z)J:5ft, iBE*^* 
t- a OTiwr & ft B& & i > 0 * ft ft & to 6 
T\ SMS^* ^ a B nJS^c T^ci^t^, fSMi 
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WJtac i ar* s#s, *ftfiLfc$fc«:jit*c iBt 
Sfrt,^ C<Dffi«B, VPMASKO— SP3asflfi©8|J»J: 
f)§SCCW*3fti»^3&S&tl, VPMASK^WS 
ME K E Y J: 0 CC W£ $ ft £ ft § lit 

It L I f c B , ft ASB C K tc -X > r ffi *> to^ S C i 

tctoa^rfe, ftA^v s&coii-cHfe^DSc i#sr 

[0035] &&mmmxu, *©^wi«B2-3© 

3GHr>XrA^6 2G TDMAIf^XfA 
^OO-5>^0«tB, JS^ftXifeflttBB. 12 8b' 
* F<D^>^Atcfp6!fi3ftfcCKii*SW9(0, ^ft^ 

584t:?hv swcasRrs. awwaawwiB, 5 

8 4 fcf* hVSilr^ffil -eft* 128fcTyhCK 

o©^>#AHgifcf , &teJ:CJfh**6aSo ccd^JWJ 
Sttt Cft6BaWO«WB'T?Ba:<, «A#*^t?it 

r «> & c t #r a 4£ w s ft ft: ^ > ^AKit* 

^ D Cft60&Hf^>yA|«»iB, *i«tttt7>^ 
A*^i7)ltm£ti& 0 Cft6co^>^A^^^;l/B, 
etTKKtSSftSJ: 5 tc, ^ ^ ^^Mtfci^P > * 

o<D^>^ABH»Bf , gfci^'htfel fteJiCJfg 
Bl 2 8 fcf^ hA^^:4 5 6 fcf y h-7>#Affi&Cv? f 
hB4 5 6b'^A^4 12 8fc + 7h7>^A 

[0 0 3 6] HI IB, Hi (DiifiV^^ACDmb^ b 
ilKEY 1 *S2(Dai^fA0n fcf^ hMUKE 
Y2 CC^T&fcftoa^ft^X^AOlft&ie^fftO— 
HJfeJf^CD^ftH*^^-. mfcf^KEYlB, v > ^ 
AKSfcf (^n^*2 0 0) K-^it6ft, 7>^Ait 

l^BSIl ©^HiiRKv^ t*>^-r4o 3 Glfi^f 
A*?>2G TDMAMft^X^ACCP- ^ >^t5H 
tB, fft^XfAB. 1 2 8 fcfy fJICK*5 84 tT 
^KVPMASK. SMEKEYMC^8rr&o 1 
2 8tfyh«CKB, 7>^A«f (^9?20 
0) tc^^.6ft, 7>^AiifBl 2 8 fcf* hCK 

4 5 6 b ^ h7>^Ag[*5W»l CDtpraffiRCC 
7^t 4 >m o cprafflRB^>^A|H^[h (^n^^ 
2 10)CC^^.6ft, 7>^AiihB, n-mfcf^f 

h (210) CDmt ^ hm^TB, mfcT^ hKEYlif 
ffeWK&fflffl (XOR2 2 0 ) *i6ft, mtr^KD»2 
©cpffl|iT*S*s!c3ftS 0 3GI^>XfA^6 2GT 
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^™iRi«h (210) i€-5-?Lhti& 0 mmh 

(2 10) tt4 5 6 ^7MR^128t^7>^A 
$tfC^*b>^U -tCD^>3fA«tt 1 2 8 b * hCK 
iCDSfffiWi§iMffi^i6n, 1 2 8 b * KD»2<D*|« 

[0 0 3 7 1011 OHS6j|5«rtt, mb * h tpRBfilT 
B, 7>^Altg (^a^2 30)K4i6h5 B 
7>^'AiSg (7^n^23 0 ) B, f-f 2 -^ 

yARIln-ml^? h *lffl«R iS^flWHHft (XOR 

240) ^kthti, waito— 
sn& 0 coiaeMras, fivit i -xom, mm<D 

Sift -51^ Bit©— SUi Itffll^ CiOTt§fKE Y 
2Q— B|Srft£ 0 COlWltK, nfcf*b«KEY 
2B, mtf?> h©»2©ifratfT££feCC, n-mb* 
F-ffiV£r^tf 0 3Gifr>XrA^?)2G T D MAS 

(2 3 0 ) B 1 2 8 b * h tfJ|ffl«T£ 4 5 6 t'^7> 
#Atfett^b>^U *©^>^A«[tt4 5 6 fcf * h 
tpfflffiTiOSPffiWIIffiW (XOR2 40) 
4 5 6 fcf* b«ffiV#^£3ft& 0 4 5 6 tf* httVto 
±^1 2 8 b* FtfifflfTil CO^jT'B, 2G TD 
MA^fAiZ)fc&©VPMA S KfciffSMEKEY 
tC^f iJT& C i £ 5 8 4 b * h §MtK E Y 2 £7f2 

[0 0 3 8] 3G^fA(DCK5&^2G TDMA^> 
A© V PMA S Kfc <£ [f S ME K E Y^0l^^ 

1. r= f (CK) /* f ^fimr^c4tcj:0 l 
2 8 fcf* h CK#>64 5 6 b* HB£ffrS* / 

2. T=h (R) XOR CK /* hiffl^tl 

2 8 b* nisms* / 

3. V=g (T) XOR R /* g»t4 5 

4. m^T, v /* 5 8 4b-* bm&mti* / 

[0 0 3 9] m 1 2B, S2©lf^fA0n fcf* h 
flfilKEY2£, 0 1 CDMff^X^ACDmb* hilfBK 
E Y 1 KX*OTRTyt»^**^^^A<D»^J* 

jfeo— saiijgjii©*niar*s. cq^^stcb, n 

b*hg|ffiKEY2B, n-mfcT* h©#l©fiKJ*S 
^ttffiVi, mb* K3D»2©aB43 k ft*l^BfiTi6C» 
f($n^ 0 mb*HBTB, 7>^'Aiig (:/U*^ 
2 5 0) iC-^-TLhtl, 7>^Aitgft mb * t-?*- 
£?"J£rn -mb* fc'>^T5 B n- 

mb* b^>#AffcB, n-mfcT* hiMSViSPffiWIft 
3ft] (XOR2 6 0) n - mb * 1- CDgl 1 CD 

62 G TDMA^Xf-AtCP- = >^ltIS«t 
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B, a^^fAit 5 8 4 b* (VPMASK, 
SMEKEY) §1 2 8fc'^ MCKtC^TSc 12 
8 b* HiffiSUdTtt, 7>^'Aiig (^O^Z5 
0) fC-*M.6ft, ^>#ABH»gttl 2 8 b* H44 
5 6 b* h ^>#Aifc&CV* f>^TS B 4 56 b* f 
^>#AifcB, 4 5 6b* hitflViSNfeKnUlffl (X 
OR2 6 0) 4i6n, 4 5 6 b* KD» 1 CD^IfflfiR 

[ 0 0 4 0 ] m 1 2 ©UttJgft-CB:, n - m fcf * b <DW 
io lcr>*raiiRtt^>yABB»h (7^^2 7 0 ) fC^ 
^6fo£ D 7>^'Aiih (7"n^2 7 0) li- 
mb* hf-^mlf^ h^>#A$Wcv*b°>^ 
U mt'^7>^AS(t mb* H«BTi»ffiflejtt 
IfO(XOR2 8 0) «i££)fil£> 

KE Yl#S£fiS3ft£„ «^^^^3G^XfA^ 
62 G TDMA^fAicn- 5 >^0tR5Wt? 
B, 7>^'Aiih (:/U*^2 7 0)B, 4 5 6 b* 
h^lMR^ 12 8b* h ^>#A8fcfC7* b>#u 
20 1 2 8 b* h7>^AjRtt 1 2 8 b* HHBTi^ffe 
ftttOffl (XOR2 8 0) ££6*1, 12 8b*HHC 

[0 0 4 1] 2G T DMA^Xf ACDV PMA SKfe 
±CJf SME KE Y^6 3 G^XfACDCK^i^f 

-So 

1, T\ V£5 84b* FA^J^l^ /* TBI 2 
8b*F-gfcS\ VB4 5 6 b* hgB^* / 

2, R=g (T) XOR V /* T\ V*/Bl> 
30 T 4 5 6 b * h {BR *fpJSSE* / 

3, CK=h (R) XOR T 

[0 0 4 2] ^>#A|«ifcf, gWO'hft Kyis* 

>yAH«f, <fte<fctfh*SiiS*&fc&K:, S HA - 
K MD5, R I PE-MDiLr^tJ6n€>M^CDi:^ 

Wfctt* ftSfiSOA**S0©fi3©ffl*K:^yfcr>y 

v* b>^TSCl4CCftS 2o0A*4Ioli5J:iB 
ttftl^ SHA-l^^r>^iiW^^ SH 
A- 1 ^ * v^M^tD^PfmUBl 6 0 b* hfZlS!^ 
^fiKlV) ^L, 1 6 0 b* Mttftccv* b>^ 
3^55 12 b* hAM^i^^^fP- 
I VBSHA - l^*^^Mt5[CD/c^CDSTO^^a 
3ns I VKR5E3h4 0 -^n-Ffct, ffi^?cDA*?[ 
50 Sfc, SHA (Type, Count, Input, Pa 
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d) £$t?r<fc3 0 o /c/cLTypettf^0itf, 

sHA*wafep?^mrcitcao, counties 

«f\ ff*Sl*Bh-^(DA*5l«r*a. Padi25 1 
2 fcf * h s ha^^p- Frtoaootr^r b§|5#£Ssb 
afc*(D0ffir*a, WTtciBtgsn^cDts, sha£ 

S H A (Type, Count, Input, Pad) 10 

f (CK) : SHA ( 1, 1, CK, pad) 

SHA (1,2, CK, pad) 

S H A ( 1 , 3 4 CK, pad)mod2M36 

h (R) :SHA(2, 1, R. pad)mod2M 

2 8 

g (T) : SHA (3, 1, T, pad) 

SHA (3, 2, T, pad) 

SHA (3, 3, T, pad) mod2 A 136 

f (CK) : E c K ( 1 ) : E c K (2) ; E 
c k (3) ; E c k (4) mo d 2 * 7 2 
h (R) : E K 0 (Rl XOR 5) XOR E K 0 
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Rcts^T 1 . . . 4fcHf#ffcT£C£&cj:Q£jsJc 30 
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3G^fAS^5W"CB, TCD^T, isJ:^ ftii 

rfe, R=g (T) XOR V^lf»T^CiCCJ:o 

tJSbraS^c CK-h (R) XOR T*SI 50 
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(57) ABSTRACT 

The present invention is a key conversion system for deter- 
ministically and reversibly converting a first key value of a 
first communications system into a second key value of a 
second communication system. For example, the key con- 
version system generates a first intermediate value from at 
least a portion of the first key value using a first random 
function. At least a portion of the first intermediate value is 



provided to a second random function to produce a second 
value. An exclusive-or is performed on at least a portion of 
the first key value and at least a portion of the second value 
to generate a second intermediate value. At least a portion of 
the second intermediate value is provided to a third random 
function to produce a third value. By performing an exclu- 
sive-or on at least a portion of the third value and at least a 
portion of the first intermediate value, the key conversion 
system produces at least a first portion of the second key 
value, and at least a second portion of the second key value 
is produced as the second intermediate value. The key 
conversion system is reversible or bi-directional in that, if 
the wireless unit is handed off back to the first communi- 
cations system, the second key value of the second commu- 
nications system is converted back to the first key value of 
the first communications system. For example, the key 
conversion system provides the at least second portion of the 
second key value to the third random function to produce the 
third value. The first intermediate value is generated by 
performing an exclusive-or on the first portion of the second 
key value and the third value. Using the second random 
function, the key conversion system generates the second 
value from the first intermediate value and produces at least 
a portion of the first key by performing an exclusive-or on 
the second value and the second portion of the second key 
value. 
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KEY CONVERSION SYSTEM AND METHOD 

BACKGROUND OF THE INVENTION 
[0001] 1. Field of The Invention 

[0002] The present invention relates to communications; 
more specifically, the conversion of keys for first and second 
communications systems as the wireless unit roams between 
the first and second communications systems. 

[0003] 2. Description of Related Art 

[0004] FIG. 1 depicts a schematic diagram of first and 
second wireless communications systems which provide 
wireless communications service to wireless units (e.g., 
wireless units Yla-c) that are situated within the geographic 
regions 14 and 16, respectively. A Mobile Switching Center 
(e.g. MSCs 20 and 24) is responsible for, among other 
things, establishing and maintaining calls between the wire- 
less units, calls between a wireless unit and a wireline unit 
(e.g., wireline unit 25), and/or connections between a wire- 
less unit and a packet data network (PDN), such as the 
internet. As such, the MSC interconnects the wireless units 
within its geographic region with a public switched tele- 
phone network (PSTN) 28 and/or a packet data network 
(PDN) 29. The geographic area serviced by the MSC is 
divided into spatially distinct areas called "cells." As 
depicted in FIG. 1, each cell is schematically represented by 
one hexagon in a honeycomb pattern; in practice, however, 
each cell has an irregular shape that depends on the topog- 
raphy of the terrain surrounding the cell. 

[0005] Typically, each cell contains a base station (e.g. 
base stations 22a-e and 26a-e), which comprises the radios 
and antennas that the base station uses to communicate with 
the wireless units in that cell. The base stations also com- 
prise the transmission equipment that the base station uses to 
communicate with the MSC in the geographic area. For 
example, MSC 20 is connected to the base stations 22a-e in 
the geographic area 14, and an MSC 24 is connected to the 
base stations 26a -e in the geographic region 16. Within a 
geographic region, the MSC switches calls between base 
stations in real time as the wireless unit moves between 
cells, referred to as call handoff . Depending on the embodi- 
ment, a base station controller (BSC) can be a separate base 
station controller (BSC) (not shown) connected to several 
base stations or located at each base station which admin- 
isters the radio resources for the base stations and relays 
information to the MSC. 

[0006] The MSCs 20 and 24 use a signaling network 32, 
such as a signaling network conforming to the standard 
identified as TIA/EIA-41-D entitled "Cellular Radiotele- 
communications Intersystem Operations," December 1997 
("IS-41"), which enables the exchange of information about 
the wireless units which are roaming within the respective 
geographic areas 14 and 16. For example, a wireless unit 12a 
is roaming when the wireless unit 12a leaves the geographic 
area 14 of the MSC 20 to which it was originally assigned 
(e.g. home MSC). To ensure that a roaming wireless unit can 
receive a call, the roaming wireless unit 12a registers with 
the MSC 24 in which it presently resides (e.g., the visitor 
MSC) by notifying the visitor MSC 24 of its presence. Once 
a roaming wireless unit 12a is identified by a visitor MSC 
24, the visitor MSC 24 sends a registration request to the 
home MSC 20 over the signaling network 32, and the home 



MSC 20 updates a database 34, referred to as the home 
location register (HLR), with the identification of the visitor 
MSC 24, thereby providing the location of the roaming 
wireless unit 12a to the home MSC 20. 

[0007] After a roaming wireless unit is authenticated, the 
home MSC 20 provides to the visitor MSC 24 a customer 
profile which indicates the features available to the roaming 
wireless unit, such as call waiting, caller id, call forwarding, 
three-way calling, and international dialing access. Upon 
receiving the customer profile, the visitor MSC 24 updates 
a database 36, referred to as the visitor location register 
(VLR), to provide the same features as the home MSC 20. 
The KLR, VLR and/or the authentication center (AC) can be 
co-located at the MSC or remotely accessed. 

[0008] If a wireless unit is roaming between wireless 
communications systems using different wireless communi- 
cations standards, providing the wireless unit with the same 
features and services in the different wireless communica- 
tions systems is complex if even feasible. There are cur- 
rently different wireless communication standards utilized in 
the U.S., Europe, and Japan. The U.S. currently utilizes two 
major wireless communications systems with differing stan- 
dards. The first system is a time division multiple access 
system (TDMA) and is governed by the standard known as 
IS- 136, the second system is a code division multiple access 
(CDMA) system governed by the standard known as IS -95. 
Both communication systems use the standard known as 
IS-41 for intersystem messaging, which defines the authen- 
tication procedure. 

[0009] In TDMA, users share a frequency band, each 
user's speech is stored, compressed and transmitted as a 
quick packet, using controlled time slots to distinguish them, 
hence the phrase "time division". At the receiver, the packet 
is decompressed. In the IS-136 protocol, three users share a 
given carrier frequency. In contrast, CDMA uses a unique 
code to "spread" the signal across the wide area of the 
spectrum (hence the alternative name -spread spectrum), and 
the receiver uses the same code to recover the signal from 
the noise. A very robust and secure channel can be estab- 
lished, even for an extremely low-power signal. Further, by 
using different codes, a number of different channels can 
simultaneously share the same carrier signal without inter- 
fering with each other. Both CDMA and TDMA systems are 
defined for a Second Generation (2G) and Third Generation 
(3G) phases with differing requirements for user information 
privacy or confidentiality. 

[0010] Europe utilizes the Global System for Mobiles 
(GSM) network as defined by the European Telecommuni- 
cations Standard Institute (ETSI). GSM is a TDMA stan- 
dard, with 8 users per carrier frequency. The speech is taken 
in 20 msec windows, which are sampled, processed, and 
compressed. GSM is transmitted on a 900 MHz carrier. 
There is an alternative system operating at 1.8 GHz (DCS 
1800), providing additional capacity, and is often viewed as 
more of a personal communication system (PCS) than a 
cellular system. In a similar way, the U.S. has also imple- 
mented DCS-1900, another GSM system operating on the 
different carrier of 1.9 GHz. Personal Digital Cellular (PDC) 
is the Japanese standard, previously known as JDC (Japa- 
nese Digital Cellular). PDC is a TDMA standard similar to 
the U.S. standard known as IS-54 protocol. 

[0011] The GSM network utilizes a removable user iden- 
tification module (UIM) which is a credit card size card 



US 2002/0071558 Al 



2 



Jun. 13, 2002 



which is owned by a subscriber, who slides the UIM into any 
GSM handset to transform it into "their" phone. It will ring 
when their unique phone number is dialed, calls made will 
be billed to their account; all options and services connect; 
voice mail can be connected and so on. People with different 
UIMs can share one "physical" handset, turning it into 
several "virtual" handsets, one per UIM. Similar to the U.S. 
systems, the GSM network also permits "roaming", by 
which different network operators agree to recognize (and 
accept) subscribers from other wireless communications 
systems or networks, as wireless units (or UIMs) move. So, 
British subscribers can drive through France or Germany 
and use their GSM wireless unit to make and receive calls 
(on their same UK number), with as much ease as an 
American businessman can use a wireless unit in Boston, 
Miami, or Seattle, within any one of the U.S. wireless 
communications system. The GSM system is defined as a 
Second Generation (2G) system. 

[0012] The third generation (3G) enhancement of the 
GSM security scheme is defined in the Universal Mobile 
Telecommunications Service (UMTS) set of standards, and 
specifically for the security in the standard identified as 
3GPP TS-33.102 "Security Architecture" specifications. 
This security scheme with slight variations will be used as 
a basis for the worldwide common security scheme for all 
3G communications systems, including UMTS, TDM A, and 
CDMA. 

[0013] The 2G GSM authentication scheme is illustrated 
in FIG. 2. This authentication scheme includes a home 
location register (HLR) 40, a visiting location register 
(VLR) 50, and a wireless unit or mobile terminal (MT) 60, 
which includes a UIM 62. When the mobile terminal 60 
places a call, a request is sent to the home location register 
40, which generates an authentication vector AV, also called 
"triplet" (RAND, SRES, K c ) from a root key IQ. The triplet 
includes a random number RAND, a signed response SRES, 
and a session key K c . The triplet is provided to the visiting 
location register 50, which passes the random number 
RAND to the mobile terminal 60. The UIM 62 receives the 
random number RAND, and utilizing the root key IQ, the 
random number RAND, and an algorithm A3, calculates a 
signed response SRES. The UIM 62 also utilizes the root key 
and the random number RAND, and an algorithm A8 to 
calculate the session key IQ. The SRES, calculated by the 
UIM 62, is returned to the visiting location register 50, 
which compares this value from the SRES received from the 
home location register 40, in order to authenticate the 
subscriber using the mobile terminal 30. 

[0014] In the GSM "challenge/response" authentication 
system, the visiting location register 50 never receives the 
root key IQ being held by the UIM 32 and the home location 
register 40. The VLR 50 also does not need to know the 
authentication algorithms used by the HLR 40 and UIM 62. 
Also, in the GSM authentication scheme, the triplet must be 
sent for every phone call by the home location register 40. 
RAND is 128 bits, SRES is 32 bits, and K c is 64 bits, which 
is 224 bits of data for each request, which is a significant 
data load. The main focus of this description is the 64 bits 
long K c session ciphering key which is used for user infor- 
mation confidentiality. When the mobile terminal roams into 
another serving system while in the call, the session key K c 
is forwarded from the old VLR to the new target serving 
system. 



[0015] FIG. 3 shows the UMTS security scheme which is 
an enhancement to the 2G GSM scheme. Similar to the GSM 
scheme, when the mobile terminal 90 places a call, a request 
is sent to the home location register 70, which sends an 
authentication vector — AV to the Visited Location Register 
(VLR) 80 which contains five elements instead of the three 
elements of a triplet, and therefore is called "quintuplet". 
This vector contains the 128 bit RAND, the 64 bits SRES, 
the AUTN value which carries the authentication signature 
of the home network, and two session security keys: the 128 
bit ciphering key CK and the 128 bit integrity key IK. These 
latter two keys, CK and IK, are the focus of this description. 

[0016] The vector is provided to the visiting location 
register 80, which passes the random number RAND and the 
AUTN to the mobile terminal 90. The UIM 92 receives the 
random number RAND, and utilizing the root key IQ, the 
random number RAND, and an defined algorithmic func- 
tions, validates the AUTN and calculates a signed response 
SRES. The UIM 92 also utilizes the root key IQ and the 
random number RAND and defined algorithmic functions to 
calculate the session keys CK and IK. The SRES, calculated 
by the UIM 92, is returned to the visiting location register 
80, which compares this value from the SRES received from 
the home location register 70 in order to authenticate the 
subscriber using the mobile terminal 90. A focus of this 
description are the 128 bits long session ciphering key CK 
and 128 bits long session integrity key IK which are used for 
user information confidentiality and session integrity pro- 
tection. Once the subscriber is successfully authenticated, 
the VLR 80 activates the CK and IK received in this 
authentication vector. If the mobile terminal roams into 
another serving system while on the call, the CK and IK are 
sent to the new target serving system. 

[0017] The 2G IS-41 authentication scheme, used in U.S. 
TDMA and CDMA systems, is illustrated in FIG. 4. This 
authentication scheme involves a home location register 
(HLR) 100, a visiting location register (VLR) 110, and a 
mobile terminal (MT) 120, which can include a UIM 122. 
The root key, known as the A_key, is stored only in the HLR 
100 and the UIM 122. There is a secondary key, known as 
Shared Secret Data SSD, which is sent to the VLR 110 
during roaming. SSD is generated from the A_key using a 
cryptographic algorithm. The procedure for generating the 
SSD is described elsewhere and is known to those skilled in 
the art. When the MT 120 roams to a visiting network, the 
VLR 110 sends an authentication request to the HLR 100, 
which responds by sending that subscriber's SSD. Once the 
VLR 110 has the SSD, it can authenticate the MT 120 
independently of the HLR 100, or with the assistance of the 
HLR 100 as is known to those skilled in the art. The VLR 
110 sends a random number RAND to the UIM 122 via the 
MT 120, and the UIM 122 calculates the authentication 
response (AUTHR) using RAND and the stored value of 
SSD in UIM 122. AUTHR is returned to the VLR 110, 
which checks it against the value of AUTHR that it has 
independently calculated in the same manner. If the two 
AUTHR values match, the MT 120 is declared valid. This 
process repeats when the wireless unit attempts to access the 
system, for instance, to initiate a call, or to answer a page 
when the call is received. 

[0018] In these cases, the session security keys are also 
generated. To generate session security keys, the internal 
state of the computation algorithm is preserved after the 
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authentication calculation. Several session security keys are 
then calculated by the UIM 122 and the VLR 110 using the 
current value of SSD. Specifically, the 520 bits Voice 
Privacy Mask (VPM) is computed, which is used for con- 
cealing the TDMA speech data throughout the call. This 
VPM is derived at the beginning of the call by the UIM and 
VLR, and, if the mobile roams into another serving system 
during the call, the VPM is sent to the new serving system 
by the VLR. When the call is concluded, the VPM is erased 
by both the UIM and the serving VLR. Likewise, the 64 bits 
Signaling Message Encryption Key (SMEKEY) is com- 
puted, which is used for encrypting the TDMA signaling 
information throughout the call. This SMEKEY is derived at 
the beginning of the call by the UIM and VLR, and, if the 
mobile roams into another serving system during the call, 
the SMEKEY is sent to the new serving system by the VLR. 
When the call is concluded, the SMEKEY is erased by both 
the UIM and the serving VLR. 

[0019] The 2G CDMA scheme uses a similar method of 
key distribution, except, instead of the 520 bits VPM, it is 
using the 42 Least Significant Bits (LSB) of the VPM as a 
seed into the Private Long Code Mask (PLCM). This PLCM 
is used as an additional scrambling mask for the information 
before its spreading. The 42-bit PLCM is consistent through- 
out the call and is sent to the new serving system by the VLR 
if the mobile roams into another serving system. The 
SMEKEY is used in the same way as in the TDMA based 
scheme. 

[0020] The IS-41 3G security scheme uses the UMTS 
security scheme, which is based on the delivery of the 
128-bits ciphering key CK and 128-bits integrity key IK to 
the visited system VLR, while the same keys are computed 
by the UIM. 

[0021] Key conversions as a wireless unit roams between 
communications systems should be performed in a way that 
even if lower security of 2G schemes and algorithms is 
compromised and partial keys are recovered by the intruder, 
the 3G session keys would still maintain the same level of 
security. Such conversions will allow a subscriber to "roam 
globally" maintaining the security of communications data 
and integrity of communications session. 

SUMMARY OF THE INVENTION 

[0022] The present invention is a key conversion system 
for deterministically and reversibly converting a first key 
value of a first communications system into a second key 
value of a second communication system. For example, the 
key conversion system generates a first intermediate value 
from at least a portion of the first key value using a first 
random function. At least a portion of the first intermediate 
value is provided to a second random function to produce a 
second value. An exclusive -or is performed on at least a 
portion of the first key value and at least a portion of the 
second value to generate a second intermediate value. At 
least a portion of the second intermediate value is provided 
to a third random function to produce a third value. By 
performing an exclusive -or on at least a portion of the third 
value and at least a portion of the first intermediate value, the 
key conversion system produces at least a first portion of the 
second key value, and at least a second portion of the second 
key value is produced as the second intermediate value. The 
key conversion system is deterministic in that, given a first 



key value, a wireless unit and the wireless communications 
system will determine the same second key value without 
requiring an exchange of information. 

[0023] The key conversion system is reversible or bi- 
directional in that, if the wireless unit is handed off back to 
the first communications system, the second key value of the 
second communications system is converted back to the first 
key value of the first communications system. For example, 
the key conversion system provides the at least second 
portion of the second key value to the third random function 
to produce the third value. The first intermediate value is 
generated by performing an exclusive-or on the first portion 
of the second key value and the third value. Using the second 
random function, the key conversion system generates the 
second value from the first intermediate value and produces 
at least a portion of the first key by performing an exclusive- 
or on the second value and the second portion of the second 
key value. The key conversion system provides improved 
security because even if almost all of the second key value 
is known, the first key value cannot easily be recovered. 
Similarly, if almost all of the first key value is known, the 
second key value is not easily recovered. 

BRIEF DESCRIPTION OF THE DRAWINGS 

[0024] Other aspects and advantages of the present inven- 
tion may become apparent upon reading the following 
detailed description and upon reference to the drawings in 
which: 

[0025] FIG. 1 shows a general diagram of wireless com- 
munications systems for which the key conversion system 
according to the principles of the present invention can be 
used; 

[0026] FIG. 2 is a block diagram illustrating the basic 
components of the prior art 2G global system for mobiles 
(GSM) network and security messages transmitted in the 2G 
GSM network; 

[0027] FIG. 3 is a block diagram illustrating the basic 
components of the prior art 3G UMTS network and mes- 
sages transmitted in the 3G UMTS network; 

[0028] FIG. 4 is a block diagram illustrating the basic 
components of the prior art 2G IS-41 network and messages 
transmitted in the prior art 2G IS-41 network; 

[0029] FIG. 5 is a block diagram illustrating how a user 
roams from a 2G TDMA network into a generic 3G network; 

[0030] FIG. 6 is a block diagram illustrating how a user 
roams from a generic 3G network into a 2G TDMA network; 

[0031] FIG. 7 is a block diagram illustrating how a user 
roams from a 2G CDMA network into a generic 3G network; 

[0032] FIG. 8 is a block diagram illustrating how a user 
roams from a generic 3G network into a 2G CDMA network; 

[0033] FIG. 9 is a block diagram illustrating how a user 
roams from a 2G GSM network into a generic 3G network; 

[0034] FIG. 10 is a block diagram illustrating how a user 
roams from a generic 3G network into a 2G GSM network; 

[0035] FIG. 11 is a flow diagram of an embodiment of the 
forward conversion for the key conversion system according 
to principles of the present invention; and 
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[0036] FIG. 12 is a flow diagram of an embodiment of the 
reverse conversion for the key conversion system according 
to principles of the present invention. 

DETAILED DESCRIPTION 

[0037] An illustrative embodiment of the key conversion 
system according to the principles of the present invention 
is described below which provides an improved key con- 
version for a wireless unit which roams between first and 
second wireless communications systems. The key conver- 
sion system deterministically and reversibly converts an m 
bit key value of a first communications system into an n-bit 
key value of a second communication system. In certain 
embodiments, the key conversion system use three random 
functions f, g and h where random functions f and g map an 
m bit input string into an n-m bit string resembling a random 
number, and the random function h maps an n-m bit string 
into an m bit string resembling a random number. A random 
function maps inputs to outputs such that the outputs are 
unpredictable and random looking given the input. In the 
embodiments described below, the random functions are 
random oracles where every time an input is given it maps 
to the same output. Additionally, in the embodiments 
described below, the random functions are publicly known. 
For example, the random functions are known by the wire- 
less communications system(s) involved in the intersystem 
handoff and the wireless unit. 

[0038] The key conversion system is deterministic in that, 
given an m-bit key value, a wireless unit and the wireless 
communications system will determine the same n-bit key 
value without requiring an exchange of information. The key 
conversion system is reversible or bi-directional in that, if 
the wireless unit is handed off back to the first communi- 
cations system, the n bit key of the second communications 
system is converted back to the m-bit key of the first 
communications system. The key conversion system pro- 
vides improved security because even if almost all of the n 
bit key value is known, the m bit key value cannot easily be 
recovered. Similarly, if almost all of the m bit key value is 
known, the n bit key value is not easily recovered. 

[0039] Depending on the embodiment, the key conversion 
system can provide secure, deterministic and bi-directional 
key conversion when a wireless unit roams between two 
wireless communications system, such as between an older 
communications system and a newer communications sys- 
tem. For example where the same reference numerals indi- 
cate like components, the IS-41 3G security scheme of FIG. 
5 converts, at the VLR 80 and at the wireless unit 120 (or 
122), the 520-bits VPM in combination with the 64-bits 
SMEKEY received from the VLR 110 to the 128-bit CK 
and/or 128-bit IK when the wireless unit roams into the 3G 
system from the 2G TDMA system. Conversely, as shown in 
FIG. 6, the IS-41 3G security scheme converts, at the VLR 
80 and the wireless unit 90 (or 92), the 128-bit CK and/or the 
128-bit IK to the 520-bits VPM in combination with the 
64-bits SMEKEY when the wireless unit roams into the 2G 
TDMA system from the 3G system. The VLR 80 provides 
the VPM and the SMEKEY to the VLR 110. 

[0040] As shown in FIG. 7, IS-41 3G security scheme 
converts, at the VLR 80 and at the wireless unit 120 (or 122), 
the 42-bits PLCM in combination with the 64-bits SMEKEY 
received from the VLR 110 to the 128-bit CK and/or the 



128 -bit IK when the wireless unit roams into the 3G system 
from the 2G CDMA system. Conversely, as shown in FIG. 
8, the IS-41 3G security scheme converts, at the VLR 80 and 
at the wireless unit 90 (or 92), the 128-bit CK and 128-bit 
IK to the 42-bits PLCM in combination with the 64-bits 
SMEKEY when the mobile roams into the 2G CDMA 
system from the 3G system. The VLR 80 provides the 
PLCM and the SMEKEY to the VLR 110. 

[0041] As shown in FIG. 9. the UMTS 3G security 
scheme converts, at the VLR 80 and at the wireless unit 60 
(or 62), the 64-bit Kc received from the VLR 50 to the 
128 -bit CK and/or the 128-bit IK when the wireless unit 
roams into the 3G UMTS system from the 2G GSM system. 
Conversely, as shown in FIG. 10, the UMTS 3G security 
system converts, at the VLR 80 and at the wireless unit 90(or 
92), the 128-bit CK and/or the 128-bit IK to the 64-bit 
when the wireless unit roams into the 2G GSM system from 
the 3G UMTS system. The VLR 80 provides the to the 
VLR 50. 

[0042] Accordingly, in certain embodiments, a wireless 
unit that supports enhanced subscriber authentication (ESA) 
and enhanced subscriber privacy (ESP) in a first communi- 
cations system, such as a newer 3G communications system, 
may implement multiple privacy modes to enable the wire- 
less unit to provide privacy using older algorithms in a 
second communications system, such as an older 2G TDMA 
communications system. Such a wireless unit can provide 
other forms of privacy after intersystem handoff to an MSC 
for an older second communications system that does not 
support ESP. When handoff to the older second communi- 
cations system is required, the key conversion system can 
convert the key values for the newer first communications 
system to the privacy keys needed for the older privacy 
algorithms supported by the older second communications 
system. The keys for the second communications system can 
be sent to the target MSC of the second communications 
system from the MSC of the first communications system. 
Since the key conversion system is deterministic, the wire- 
less unit will also have the keys for the second communi- 
cations system by performing the same conversion as the 
first communication system using the key conversion system 
of the present invention. 

[0043] The key conversion system maps a key(s) from a 
first system into a key(s) of a second system and back again. 
For example, when performing an intersystem handoff 
between a 3G communications system and a 2G TDMA 
system, the key conversion system can map a cipher key CK 
into a VPMASK/SMEKEY (VS) pair. In this embodiment, 
the key conversion function possesses the following prop- 
erties: 1) A 128 bit CK is mapped into a 584 bit VS; 2) The 
function is reversible and maps back a 584 bit VS into a 128 
bit CK; and 3) The function is secure in the sense that partial 
knowledge of the 584 bit key will not allow the adversary to 
recover the CK, nor will partial knowledge of 128 bit key 
CK allow the adversary to recover the 584 bit VS. In certain 
instances, for example when the call originates in a first 
communication system having a larger key value than the 
target second communications system, the conversion sys- 
tem maps the key value of the first communication system 
to a key value of a second communications system. How- 
ever, if the wireless unit returns to the first communications 
system, the key conversion system maps the second key 
value to a subsequent key value for the first communications 



US 2002/0071558 Al 



5 



Jun. 13, 2002 



system which is not necessarily the same as the original key 
value. Subsequent handoffs back to the first communications 
system from the second communications system produce a 
key value which is the same as the subsequent key value. 

[0044] For example, when performing an intersystem 
handoff for a call originating with a 2G TDMA system to a 
3G system, the key conversion system can map VPMASK/ 
SMEKEY (VS) pair into a cipher key CK. In this embodi- 
ment, the key conversion function maps the 584 bit VS into 
the 128 bit CK. If the wireless unit is handed back to the 2G 
TDMA system, the conversion system maps back the 128 bit 
CK into the 584 bit VS, but the new 584 bit VS may not be 
the same as the original 584 bit VS. Subsequent handoffs to 
the 2G TDMA system from the 3G system will maintain the 
new 584 bit VS. Although this should not effect the security 
or operation of the wireless unit, the 128 bit CK is main- 
tained the same all along in this embodiment. 

[0045] In this embodiment, the key conversion system 
includes conversion functions available at the MSC in the 
newer system and at the wireless unit which will convert key 
values, for a first communications system, such as ESP keys, 
into key values of a second communications system, such as 
keys used for older privacy algorithms. In this example, the 
conversion function should convert the 128 bit CKkey in the 
new first communication system to VPMASK/SMEKEY 
(VS) keys for the older second communication system. 
VPMASK is composed of 260 bits mask for each direction 
and SMEKEY is 64 bits long, for a total of 584 bits to be 
used by the older communication system. In case of an 
intersystem handoff from the old communication system to 
the new communication system, it may be useful for the 
conversion function to be reversible. The old communica- 
tion system does not know about the new communication 
system and will transfer all 584 bits to the new communi- 
cation system. The new communication system upon receiv- 
ing the 584 bit key will realize that it needs to recover the 
128 bit CK, and hence will compute the CK from the 584 bit 
key. 

[0046] The VS keys created at the wireless unit and the 
MSC should be the same. This means the calculation of the 
VS keys must be based solely on CK and any other quan- 
tities known by both the MSC and the wireless unit. Oth- 
erwise, any new quantities (e.g. random number) would 
have to be exchanged between the wireless unit and the 
MSC prior to the conversion. The key conversion system 
does not require the exchange of information between the 
wireless unit and the new MSC and deterministically maps 
a CK to VS keys and VS keys to a CK key. 

[0047] Additionally, weaknesses in the old communica- 
tions system should not make the new communications 
system weak. One can achieve this by making the key 
conversion function cryptographic ally one way, so that even 
if the entire key of the old communication system, such as 
the VS key in this example, is revealed, the adversary cannot 
recover the key of the new communication system, such as 
the CK key in this example. However, this will make the 
system no n- reversible and, as previously noted, the key 
conversion system should be reversible. Nevertheless, the 
key conversion system can be reversible and still provide 
almost all of the security of a non-reversible function. The 
security of the key conversion system in this example 
prevents an adversary from recovering any part of the CK 



key even if almost all of the VS key is revealed except a 
small part. The adversary can guess the small part, but he 
should not be able to do any better. This aspect is important 
because parts of VPMASK may be somewhat easy to 
recover, and the entire VPMASK may be easier to recover 
than the SMEKEY. Yet if some part of the old system is hard 
to recover than the adversary will not know anything about 
CK. A similar security can apply to CK so that a partial 
knowledge of CK should not tell the adversary anything 
about VS. 

[0048] In certain embodiments, the conversion function 
has two modes, the forward conversion and the reverse 
conversion. In the example of roaming from the 3G com- 
munications system to the 2G TDMA communications sys- 
tem, the forward conversion takes the 128 bit randomly 
created CK key and expands it to 584 bit VS key. The 
reverse conversion function takes the 584 bit VS keys and 
maps it to a 128 bit CK key. In this embodiment, the forward 
conversion function is composed of 3 random functions f, g 
and h which map a given input into a random output. In this 
embodiment, these are not secret functions but public ran- 
dom functions known to everybody, including the adversary. 
These public random functions are referred to as random 
oracles in the literature. These random oracles can be 
implemented using hash functions and block ciphers as 
described below. In this example, the three random functions 
are f, g, h where f and g map a 128 bit input into a 456 bit 
random value, and h maps a 456 bit input into a 128 bit 
random value. 

[0049] FIG. 11 shows a flow diagram of an embodiment 
of the forward conversion of the key conversion system for 
converting an m-bit key value KEY1 of a first communica- 
tions system into an n-bit key value KEY2 of a second 
communications system. The m bit KEY1 is provided to a 
random function f (block 200) which maps an m-bit string 
into an n-m bit random number or first intermediate value R. 
In the example of roaming from the 3G communications 
system to the 2G TDMA communications system, the con- 
version system converts a 128 bit key CK into a 584 bit key 
(VPMASK, SMEKEY). The 128 bit key CK is provided to 
the random function f (200) which maps the 128 bit CK into 
a 456 bit random number or first intermediate value R. The 
intermediate value R is provided to a random function h 
(block 210) which maps an n-m bit string into an m bit 
random number. The m-bit output of the function h (210) is 
subject to an exclusive -or (XOR 220) with the m bit KEY1 
to produce an m-bit second intermediate value T. In the 
example of roaming from the 3G communications system to 
the 2G TDMA communications system, the 456 bit inter- 
mediate value R is provided to the function h (210). The 
function h (210) maps the 456 bit value R to a 128 bit 
random number which is XORed with the 128 bit CK to 
produce a 128 bit second intermediate value T. 

[0050] In the embodiment of FIG. 11, the m-bit interme- 
diate value T is provided to a random function g (block 230). 
The random function g (block 230) maps an m bit string to 
an n-m bit random number which is subject to an exclusive - 
or (XOR 240) with the n-m bit intermediate value R to 
produce an n-m bit key value V which can be used as a key, 
keys or portion(s) of key(s). In this embodiment, the value 
V is a portion of the value KEY2 which can be used as a key, 
keys or portion(s) of key(s). In this embodiment, the n bit 
key KEY2 includes the n-m bit value V along with the m bit 
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second intermediate value T. In the example of roaming 
from the 3G communications system to the 2G TDMA 
communications system, the random function g (230) maps 
the 128 bit intermediate value T into a 456 bit random 
number which is subject to the exclusive -or (XOR 240) with 
the 456 bit intermediate value T to produce the 456 bit key 
value V. The 456 bit value V and the 128 bit intermediate 
value T form the 584 bit key value KEY2 which in this 
example can be divided into the VPMASK and the 
SMEKEY for 2G TDMA systems. 

[0051] The forward conversion of the CK of the 3G 
system to the VPMASK and SMEKEY of the 2G TDMA 
system can be written according to the following steps. 

[0052] 1. R=f(CK)/* create a 456 bit value from 128 bit 
CK by applying f */ 

[0053] 2. T=h(R) XOR CK/* create a 128 bit value 
using h */ 

[0054] 3. V=g(T) XOR R/* create a 456 bit value using 

gV 

[0055] 4. Output T,V/* output the 584 bit value */ 

[0056] FIG. 12 shows a flow diagram of an embodiment 
of the reverse conversion of the key conversion system for 
converting the n-bit key value KEY2 of the second com- 
munications system back into the m-bit key value KEY1 of 
the first communications system. In this embodiment, the n 
bit key value KEY2 is divided into an n-m bit first portion 
or value V and an m-bit second portion or value T. The m-bit 
value T is provided to the random function g (block 250) 
which maps an m-bit string into an n-m bit random number. 
The n-m bit random number is subjected to an exclusive -or 
(XOR 260) with the n-m bit key value V to produce the n-m 
bit first intermediate value R. In the example where the 
wireless unit roams back to the 2G TDMA system from the 
3G system, the conversion system converts the 584 bit key 
(VPMASK, SMEKEY) into a 128 bit key CK. The 128 bit 
key value portion T is provided to the random function g 
(250) which maps the 128 bit T into a 456 bit random 
number. The 456 bit random number exclusive- ORed (XOR 
260) with the 456 bit key value V to produce the 456 bit first 
intermediate value R. 

[0057] In the embodiment of FIG. 12, the n-m bit first 
intermediate value R is provided to a random function h 
(block 270). The random function h (block 270) maps an 
n-m bit string to an m bit random number which is subject 
to an exclusive-or (XOR 280) with the m bit key value T to 
produce an m bit key value KEY1 which can be used as a 
key, keys or portion(s) of key(s). In the example where the 
wireless unit roams back to the 2G TDMA system from the 
3G system, the random function h (270) maps the 456 bit 
intermediate value R into a 128 bit random number which is 
subject to an exclusive-or (XOR 280) with the 128 bit key 
value T to produce the 128 bit key CK. 

[0058] The reverse conversion of the VPMASK and 
SMEKEY of the 2G TDMA system to the CK of the 3G 
system can be written according to the following steps. 

[0059] 1. Set T,V to 584 bit input/* T is 128 bit part, V 
is 456 bit part */ 

[0060] 2. R =g(T) XOR V/* create 456 bit value R using 
T, V */ 

[0061] 3. CK =h(R) XOR T 



[0062] The random functions f, g and h can be imple- 
mented using hash functions and/or block ciphers. To imple- 
ment the random functions f, g, and h, which can be referred 
to as random oracles, cyptographic hash functions, such as 
the functions known as known as SHA-1, MD5, RIPE-MD, 
can be used to instantiate the random functions f, g, h. A hash 
function can be typically characterized as a function which 
maps inputs of one length to outputs of another, and given 
an output, it is not feasible to determine the input that will 
map to the given output. Moreover, it is not feasible to find 
two inputs which will map to the same output. In using a 
SHA-1 hash function, each call to the SHA-1 hash function 
has a 160 bit initial vector (IV) and takes a 512 bit input or 
pay load which is mapped into a 160 bit output. The IV is set 
to the IV defined in the standard for SHA-1 hash function. 
The payload will contain various input arguments: 
SHA(Type, Count, Input, Pad) where Type is a byte value 
which defines the various functions f, g, h. Function f and g 
will call SHA multiple times, and Count is a byte value 
which differentiates the multiple calls. Input is the input 
argument to the functions f, g, or h. Pad is zeroes to fill the 
remaining bit positions in the 512 bit SHA payload. Below 
is an example procedure for implementing the random 
function f, g and h using a hash function routine referred to 
as SHA. 

[0063] SHA(type,count,input,pad) 
[0064] f(CK): SHA(1, 1, CK, pad) 

[0065] SHA(1, 2, CK, pad) 

[0066] SHA(1, 3, CK, pad) mod 2 A 136 
[0067] h(R): SHA(2, 1, R, pad) mod 2 A 128 
[0068] g(T): SHA(3, 1, T, pad) 

[0069] SHA(3, 2, T, pad) 

[0070] SHA(3, 3, T, pad) mod 2 A 136 

[0071] Block ciphers, like AES, can be used to create 
functions f, g, and h. 

[0072] f(CK): E CK (1); E CK (2); E CK (3); E CK (4) mod 2 A 72; 

[0073] h(R): E K0 (R1 XOR 5) XOR E K0 (R2 XOR 6) XOR 
E K0 (R3 XOR 7) XOR E K0 (R4 XOR 8) 

[0074] g(T): E T (9); E r (10); E T (11); E T (12) mod 2 A 72; 

[0075] where in f(CK), CK is used as the key in the block 
cipher and 512 bit stream is produced by encrypting 1 . . . 
4 in counter mode. The last encryption is truncated from 128 
bit to 72 bit to get the needed 456 bits. In h(R), a public key 
K0 is used to encrypt the parts of 456 bit R and the resulting 
ciphertexts are exclusive-ored together. Rl, R2, and R3 are 
128 bit values and R4 is the remaining 72 bit value of R, 
padded with zeroes to complete 128 bits. 

[0076] Thus, the key conversion system provides bi-di- 
rectional, deterministic and secure conversion of a key(s) or 
portion(s) thereof between first and second communications 
systems. The key conversion system is secure in the forward 
direction in that given most of the output KEY2 (for 
example, T,V), an adversary cannot recover KEY1 (for 
example, CK). In the example with the 2G TDMA and 3G 
systems, if all of T and most V except say 64 bits are known, 
then parts of R can be recovered, but not all of R by 
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calculating R=g(T) XOR V. An attempt can be made to 
recover some of CK by performing CK=h(R) XOR T. 
However, since all of R is not known, even a bit of 
information about h(R) cannot be recovered, assuming h is 
a random function. Hence no information can be recovered 
about CK. Similarly, if all of V and part of T are known, 
except say 64 bits of T, then no information about CK can 
be recovered. Since we do not know all of T, the interme- 
diate value R cannot be calculated using g(T) XOR V. Thus 
without the intermediate value R, no progress can be made 
in recovering any information about CK. 

[0077] Similarly, the key conversion system is secure in 
the reverse direction in that given most of the output KEY1 
(for example, CK), an adversary cannot recover KEY2 (for 
example, T, V). In the example with the 2G TDMA and 3G 
systems, if a part of CK is known, no information about T,V 
can be recovered. Since we do not know all of CK, the 
intermediate value R cannot be calculated using f(CK). Thus 
without the intermediate value R, no progress can be made 
in recovering any information about T,V. 

[0078] In addition to the embodiment(s) described above, 
the key conversion system according to the principles of the 
present invention can be used which omit and/or add input 
parameters and/or random functions or other operations 
and/or use variations or portions of the described system. 
For example, the key conversion system has been described 
as converting between n bit key of a first communication 
system and an m bit key of a second communications system 
using random oracles f, g and h where the random oracles f 
and g map an m bit string to a n-m bit random number and 
the random oracle h maps a n-m bit string to an m bit random 
number. However, different random functions can be used as 
well as different or additional functions which map x bit 
strings to y bit random numbers and/or map y bit strings to 
x bit random numbers where x or y can be equal to n-m or 
m. Additionally, the m bit key value for the first communi- 
cations system can be a key, keys or portion(s) thereof, and 
the n bit key value for the second communications system 
can be a key, keys or portion(s) thereof. For example, the 
example with the 2G TDMA and 3G systems, the conversion 
is between the 128 bit CK of the 3G system and the 584 bit 
key value for the SMEKEY and VPMASK of the 2G TDMA 
system, but the conversion could be between a 256 bit key 
value of CK and IK of the 3G system and the 584 bit key 
value for the SMEKEY and VPMASK of the 2G TDMA 
system. 

[0079] In the example described above, a forward conver- 
sion is from the m bit key value of the first communications 
system to the n bit key value of the second communications 
system where the first communications system corresponds 
to the new system and the second communications corre- 
sponds to the old system and where m<n. However, depend- 
ing on the embodiment, the first communications system can 
be older, and the second communications system is newer. 
Alternatively, the forward conversion can be the conversion 
of the smaller size key value of one communications system 
to the larger bit size key value of another communications 
system, and the reverse conversion is the conversion of the 
larger bit size key value to the smaller size key value. 
Depending on the embodiment, the conversion of different, 
larger, smaller and/or the same size(s) of key value(s) 
between the different communications systems are possible. 



[0080] Furthermore, the key conversion system can be 
used to handle the intersystem handoffs described in the 
FIGS. 5-10 to convert a key, keys or portion(s) thereof from 
one communications system to the key, keys or portion(s) 
thereof of another communications system. It should be 
understood that different notations, references and charac- 
terizations of the various values, inputs and architecture 
blocks can be used. For example, the functionality described 
for the key conversion system can be performed in a home 
authentication center, home location register (HLR), a home 
MSC, a visiting authentication center, a visitor location 
register (VLR) and/or in a visiting MSC. Moreover, the key 
conversion system and portions thereof can be performed in 
a wireless unit, a base station, base station controller, MSC, 
VLR, HLR or other sub-system of the first and/or second 
communications system. It should be understood that the 
system and portions thereof and of the described architecture 
can be implemented in or integrated with processing cir- 
cuitry in the unit or at different locations of the communi- 
cations system, or in application specific integrated circuits, 
software -driven processing circuitry, programmable logic 
devices, firmware, hardware or other arrangements of dis- 
crete components as would be understood by one of ordinary 
skill in the art with the benefit of this disclosure. What has 
been described is merely illustrative of the application of the 
principles of the present invention. Those skilled in the art 
will readily recognize that these and various other modifi- 
cations, arrangements and methods can be made to the 
present invention without strictly following the exemplary 
applications illustrated and described herein and without 
departing from the spirit and scope of the present invention. 

1. A method of converting a first key value for a first 
communications system to a second key value of a second 
communications, said method comprising: 

generating a first intermediate value from at least a 
portion of said first key value using a first random 
function; 

providing at least a portion of said first intermediate value 
to a second random function to produce a second value; 

performing an exclusive -or on at least a portion of said 
first key value and at least a portion of said second 
value to generate a second intermediate value; 

providing at least a portion of said second intermediate 
value to a third random function to produce a third 
value; and 

producing at least a first portion of said second key value 
by performing an exclusive-or on at least a portion of 
said third value and at least a portion of said first 
intermediate value. 

2. The method of claim 1 comprising: 

producing at least a portion of said second intermediate 
value as at least a second portion of said second key 
value. 

3. The method of claim 1 wherein said generating com- 
prises the step of: 

providing said first key value of m bits to a first random 
function to produce said first intermediate value of n-m 
bits. 

4. The method of claim 3 wherein said first steps of 
providing and performing comprise: 
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providing said n-m bit first intermediate value to a second 
random function to produce an m bit second value; and 

performing an exclusive -or on said m bit first key value 
and said m bit second value to generate said second 
intermediate value with m bits. 

5. The method of claim 4 wherein said second step of 
providing and said step of producing comprise: 

providing said m bit second intermediate value to a third 
random function to produce a n-m bit third value; and 

performing an exclusive -or on said n-m bit third value and 
said n-m bit first intermediate value to generate an n-m 
bit portion of said second key value. 

6. The method of claim 5 comprising: 

providing said m bit second intermediate value as an m bit 
second portion of said second key value having n bits. 

7. The method of claim 2 further comprising the steps of: 

providing said second portion of said second key value to 
said third random function to produce said third value; 
and 

generating said first intermediate value by subjecting said 
first portion of said second key value to an exclusive-or 
with said third value. 

8. The method of claim 7 further comprises: 

using said second random function to generate said sec- 
ond value from said first intermediate value; and 

producing at least a portion of said first key by subjecting 
said second value to an exclusive-or with said second 
portion of said second key value. 

9. The method of claim 6 further comprises: 

providing said m bit first portion of said n bit second key 
value to said third random function to produce said n-m 
bit third value; and 

generating said n-m bit first intermediate value using an 
exclusive-or of said n-m bit second portion of said n bit 
second key value with said n-m bit third value. 

10. The method of claim 9 further comprises: 

providing said n-m first intermediate value to said second 
random function to generate an m bit second value; and 

producing said portion of said first key value having m 
bits by using an exclusive-or of said m bit first portion 
of said second key value with said m bit second value. 

11. A key conversion system for converting a first key 
value for a first communications system to a second key 
value of a second communications, said system comprising: 

processing circuitry adapted to generate a first interme- 
diate value from at least a portion of said first key value 
using a first random function to provide at least a 
portion of said first intermediate value to a second 
random function to produce a second value, to perform 
an exclusive-or on at least a portion of said first key 
value and at least a portion of said second value to 
generate a second intermediate value, to provide at least 



a portion of said second intermediate value to a third 
random function to produce a third value and to pro- 
duce at least a first portion of said second key value by 
subjecting at least a portion of said third value to an 
exclusive-or with at least a portion of said first inter- 
mediate value. 

12. The system of claim 11 wherein said processing 
circuitry further configured to produce at least a portion of 
said second intermediate value as at least a second portion 
of said second key value. 

13. The system of claim 12 wherein said processing 
circuitry further configured to provide said first key value of 
m bits to a first random function to produce said first 
intermediate value of n-m bits. 

14. The system of claim 13 wherein said processing 
circuitry further configured to provide said n-m bit first 
intermediate value to a second random function to produce 
an m bit second value and to perform an exclusive-or on said 
m bit first key value and said m bit second value to generate 
said second intermediate value with m bits. 

15. The system of claim 14 wherein said processing 
circuitry configured to provide said m bit second interme- 
diate value to a third random function to produce a n-m bit 
third value and to perform an exclusive-or on said n-m bit 
third value and said n-m bit first intermediate value to 
generate an n-m bit portion of said second key value. 

16. The system of claim 15 wherein said processing 
circuitry configured to provide said m bit second interme- 
diate value as an m bit second portion of said second key 
value having n bits. 

17. The system of claim 12 wherein said processing 
circuitry configured to provide said second portion of said 
second key value to said third random function to produce 
said third value and to generate said first intermediate value 
by subjecting said first portion of said second key value to 
an exclusive-or with said third value. 

18. The system of claim 17 wherein said processing 
circuitry configured to use said second random function to 
generate said second value from said first intermediate value 
and produce at least a portion of said first key by subjecting 
said second value to an exclusive-or with said second 
portion of said second key value. 

19. The system of claim 16 wherein said processing 
circuitry configured to provide said m bit first portion of said 
n bit second key value to said third random function to 
produce said n-m bit third value and to generate said n-m bit 
first intermediate value using an exclusive-or of said n-m bit 
second portion of said n bit second key value with said n-m 
bit third value. 

20. The system of claim 19 wherein said processing 
circuitry is configured to provide said n-m first intermediate 
value to said second random function to generate an m bit 
second value and to produce said portion of said first key 
value having m bits by using an exclusive-or of said m bit 
first portion of said second key value with said m bit second 
value. 



